CVE-2017-8450: Infoleak
Published Jun 16, 2017
·Updated
X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a document and/or field may have been able to access this information.
Affected Software
1 affected component
Elastic X-Pack=5.1.1
Event History
Jun 16, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-8450?
CVE-2017-8450 is rated as a medium severity vulnerability due to its potential for unauthorized information access.
2
How do I fix CVE-2017-8450?
To fix CVE-2017-8450, upgrade to a version of X-Pack higher than 5.1.1 where this issue has been addressed.
3
What types of requests are affected by CVE-2017-8450?
CVE-2017-8450 affects multi-search and multi-get requests within the X-Pack 5.1.1 version.
4
Who is affected by CVE-2017-8450?
Organizations using X-Pack version 5.1.1 may be affected if they have implemented document and field level security.
5
Is CVE-2017-8450 an authentication bypass vulnerability?
CVE-2017-8450 is not an authentication bypass but allows unauthorized access to certain document and field data.